CVE-2021-4148

MEDIUM

Linux Kernel < 5.14.16 - Denial of Service via Missing Sanity Check in block_invalidatepage

Title source: llm
STIX 2.1

Description

A vulnerability was found in the Linux kernel's block_invalidatepage in fs/buffer.c in the filesystem. A missing sanity check may allow a local attacker with user privilege to cause a denial of service (DOS) problem.

References (3)

Core 3
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=2026487
Exploit, Mailing List, Patch, Third Party Advisory x_refsource_misc
https://lkml.org/lkml/2021/9/12/323
Exploit, Mailing List, Patch, Third Party Advisory x_refsource_misc
https://lkml.org/lkml/2021/9/17/1037

Scores

CVSS v3 5.5
EPSS 0.0031
EPSS Percentile 22.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-354
Status published
Products (2)
fedoraproject/fedora 35
linux/linux_kernel < 5.14.16
Published Mar 23, 2022
Tracked Since Feb 18, 2026